CVE-2017-9077: High severity Google Android vulnerability
Last updated 29 November 2024
Other sources
The tcpv6synrecvsock function in net/ipv6/tcpipv6.c in the Linux kernel mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890.
Upstream patch:
https://github.com/torvalds/linux/commit/83eaddab4378db256d00d295bda6ca997cd13a52
References:
https://patchwork.ozlabs.org/patch/760370/
— Red Hat
The tcpv6synrecvsock function in net/ipv6/tcpipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-9077?
CVE-2017-9077 is a vulnerability in the Linux kernel's tcp_v6_syn_recv_sock function that can lead to denial of service or other unspecified impacts due to mishandled inheritance.
What is the impact of CVE-2017-9077?
The impact of CVE-2017-9077 includes potential denial of service attacks that local users could exploit through crafted system calls.
How do I fix CVE-2017-9077?
To fix CVE-2017-9077, upgrade to kernel versions 5.10.223-1, 5.10.226-1, 6.1.123-1, or later versions.
Which Linux kernel versions are affected by CVE-2017-9077?
Linux kernel versions up to 4.4.71 and various versions between 3.2.89 and 4.11.4 are affected by CVE-2017-9077.
Is CVE-2017-9077 specific to any operating system?
Yes, CVE-2017-9077 primarily affects the Linux operating system, including distributions like Debian and Android.